Files
ai-memory/docs
AkitaOnRailsandClaude Opus 4.8 80888360e2 feat(run): warn before --yolo, offer ai-jail, add Claude true-yolo (#983)
ai-memory run --yolo now, on an interactive TTY only (never in hook/CI/
detached paths):

- warns that --yolo runs every tool call unconfirmed, [Y/n] default-yes;
- offers to re-run inside ai-jail when it is installed, re-execing the
  original argv under `ai-jail --network --agent-state --env <NAME>…`
  (--network shares the host net namespace so the loopback ai-memory server
  stays reachable; only already-set credential/config env is forwarded);
- skips both prompts when already inside ai-jail (Linux hostname ai-sandbox
  / macOS PS1 (jail) ; fails open to showing the warning; Windows never).

Opt-in Claude "true yolo" (--true-yolo / [config] claude_true_yolo,
AI_MEMORY_CLAUDE_TRUE_YOLO) silences the pauses --dangerously-skip-permissions
leaves: sets the CLAUDE_CODE_DISABLE_*_RM_* env vars and injects
--settings bypassPermissions. Claude-only, off by default, sandbox-first.

Detection and argv assembly are pure/OS-explicit (ai-memory-workstream::jail)
with unit tests for every branch; a CLI integration suite asserts the argv
against the real ai-jail via --dry-run (skips cleanly when ai-jail/bwrap are
absent). Design: docs/design-yolo-safety-ai-jail.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-29 15:24:14 -03:00
..
2026-09-28 21:18:08 -03:00